version 1.433, 2003/03/04 13:03:43 |
version 1.434, 2003/03/05 19:58:18 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=lprm></a> |
|
<li><font color=#009000><strong>010: SECURITY FIX: March 5, 2003</strong></font><br> |
|
A fix for an |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lprm&sektion=1">lprm(1)</a> |
|
bug made in 1996 contains an error that could lead to privilege escalation. |
|
For OpenBSD 3.2 the impact is limited since |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lprm&sektion=1">lprm(1)</a> |
|
is setuid daemon, not setuid root. |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch">A |
|
source code patch exists which remedies the problem</a>. |
|
<p> |
<a name=sendmail></a> |
<a name=sendmail></a> |
<li><font color=#009000><strong>009: SECURITY FIX: March 3, 2003</strong></font><br> |
<li><font color=#009000><strong>009: SECURITY FIX: March 3, 2003</strong></font><br> |
A buffer overflow in the envelope comments processing in |
A buffer overflow in the envelope comments processing in |